Darktrace AI’s Antigena helps stop ransomware attack at Dordogne GHT
Ryuk had previously overthrown city councils and attacked over 200 US hospitals in 2021
French hospital group Dordogne Groupements Hospitaliers de Territoire (Dordogne GHT) has successfully contained and stopped a ransomware attack utilizing Darktrace AI’s autonomous response technology Antigena.
In 2021, Dordogne GHT installed Darktrace's artificial intelligence (AI)-based detect, respond technologies to guard against threats in all 11 of its hospitals, particularly for medical and corporate devices pertaining to accident and emergency departments.
The system was soon put to test when Dordogne GHT encountered a notorious ransomware strain called Ryuk, which targets critical public sectors organizations worldwide.
Russian cybercriminal group Wizard Spider has been attributed to creating the ransomware. Ryuk essentially combines advanced encryption techniques before requesting a high ransom for a private decryption key. Ryuk is also one of the first ransomware strains to encrypt network drives and resources.
Darktrace AI was alerted to the first signs of the attack via some basic .dat files being downloaded onto one of the hospital’s devices through an unknown IP address. Using AI, Darktrace’s Antigena thwarted the breach, saving medical devices from being corrupted.
"At a time when national cybersecurity agencies are urging organizations to be hyper-vigilant and lock down their systems, we can be in little doubt that defenders of healthcare systems will be working to keep the bad guys out," commented Justin Fier, VP of tactical risk and response at Darktrace.
"Autonomous response technology that uplifts human security teams by allowing them to make strategic decisions while the AI stops the attack before it causes disruption is critical in defending organizations vital to everyday life," added Fier.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
-
Rubrik teams up with Wipro to launch 'enterprise resilience as a service' schemeNews The new joint service aims to sharpen enterprise cyber resilience and recovery capabilities
-
Can responsible AI beat hallucinations?Businesses are more eager than ever to implement AI in their workflows, but ambition doesn’t always translate into success
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals